SSL VPN using Azure MFA with SAML SSO not working
Hello,
we have been experiencing issues with ssl vpn access from MacOs devices using forticlient 7.0.
The vpn uses Azure MFA with SAML SSO authentication.
The user can access the vpn via web browser but it's not a practical solution.
When accessing using forticlient the following error is displayed "The response from https://vpn.xx.xx:4443 was invalid".
From the Fortigate logs we have extracted the following error: "sslConnGotoNextState:301 error (last state: 1, closeOp: 0)"
We've researched the issue and found that fortitray had to be enabled or else vpn would not work, even this didn't resolve our issue.
We're aware of certain known issues for this vpn configuration specific for the forticlient macos releases:
https://docs.fortinet.com/document/forticlient/7.0.0/macos-release-notes/124818/known-issues
We' would like to know if it's possible to determine which of these bugs is related and if there's any workaround to apply until fortinet resolves it.
Any suggestion on the matter would be appreciated.
Thank you
Peter
